Vulnerability Description
The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3.6.10 allow local users to overwrite arbitrary files via a symlink attack on a /var/tmp/##### temporary file.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sgi | Performance Co-Pilot | <= 3.6.9 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00024.html
- http://www.securityfocus.com/bid/56656
- https://bugzilla.novell.com/show_bug.cgi?id=782967
- https://bugzilla.redhat.com/show_bug.cgi?id=875842
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00024.html
- http://www.securityfocus.com/bid/56656
- https://bugzilla.novell.com/show_bug.cgi?id=782967
- https://bugzilla.redhat.com/show_bug.cgi?id=875842
FAQ
What is CVE-2012-5530?
CVE-2012-5530 is a vulnerability with a CVSS score of 2.1 (LOW). The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3.6.10 allow local users to overwrite arbitrary files via a symlink attack on a /var/tmp/##### temporary file.
How severe is CVE-2012-5530?
CVE-2012-5530 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-5530?
Check the references section above for vendor advisories and patch information. Affected products include: Sgi Performance Co-Pilot.